1

Issue: SPF Soft Fail and No DMARC Record Found


M
Muhammad Tajammul

Hi Team
Hope you are doing well.
As a beginner security researcher I found a vulnerability in your website.
Issue: SPF Soft Fail and No DMARC Record Found
Domain boardroom.io is vulnerable to Email Spoofing.
Because of the following SPF and DMARC record:
SPF record lookup and validation for: boardroom.io
Found v=spf1 record for boardroom.io:
v=spf1 include:dc-aa8e722993._spfm.boardroom.io ~all
As you can see the symbol at last which is (~all) is the issue, which should be replaced by Hyphen (-all) symbol.
Please refer to the digital ocean article at the end of email for understanding.
DMARC record lookup and validation for: boardroom.io
No DMARC Record Found
Fix:
1) Publish DMARC Record.
2) Enable DMARC Quarantine/Reject policy
3) Your DMARC record should look like
v=DMARC1; p=reject; sp=none; pct=100; ri=86400; rua=mailto:info@domain.com

You can check your DMARC record form here
mxtoolbox.com/emailhealth/boardroom.io/
Also No DKIM Found
www.digitalocean.com/community/tutorials/how-to-use-an-spf-record-to-prevent-spoofing-improve-e-mail-reliability
Please also refer to the below articles for resolving these issues
(For SPF)
support.google.com/a/answer/33786
(For DMARC)
support.google.com/a/answer/2466580
Please find the Attached Screenshot of Domain Health Report.
And after evaluation if the technical team considered this issue as significant, please do let me know the reward of the reported issues.
With Thanks and Regards
Muhammad Tajammul

A

Activity Newest / Oldest

M

Muhammad Tajammul